-
Notifications
You must be signed in to change notification settings - Fork 0
Fix: authenticate release fetches through checkout #137
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,6 +1,6 @@ | ||
| { | ||
| "schema_version": 1, | ||
| "sequence": 63, | ||
| "id": "CHG-0063-prepare-aps-v1-1-0-atomically-build-and-test-a-portable-linux-bundle-align-hom", | ||
| "sequence": 64, | ||
| "id": "CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be", | ||
| "acknowledged_collisions": [] | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,19 @@ | ||
| { | ||
| "approvals": [ | ||
| { | ||
| "gate": "definition", | ||
| "actor": "codex", | ||
| "timestamp": 1785303728, | ||
| "digest": "ad92603b2d7a23f5d3a0a33ed40e518bbc335ea1ce30fbc2333a163a310f9c23", | ||
| "note": "Approved targeted CI authentication repair after two identical release fetch failures." | ||
| }, | ||
| { | ||
| "gate": "definition", | ||
| "actor": "codex", | ||
| "timestamp": 1785303960, | ||
| "digest": "88f806418c29a76c109b528f669ea49b8ecef20b3bfab2d16fb8a15626339ff3", | ||
| "note": "Refreshed after adding the provenance regression contract to affected paths." | ||
| } | ||
| ], | ||
| "reopenings": [] | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,24 @@ | ||
| --- | ||
| id: CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be | ||
| state: implementing | ||
| type: bug_fix | ||
| base_commit: 7373d124ebb3823c1f7f19651dfffe4d7ed83f51 | ||
| --- | ||
|
|
||
| # Fix release workflow fetch authentication so signed tags and attest notes can be fetched on GitHub-hosted runners | ||
|
|
||
| ## Intent | ||
|
|
||
| Fix release workflow fetch authentication so signed tags and attest notes can be fetched on GitHub-hosted runners | ||
|
|
||
| ## Affected Canonical Specs | ||
|
|
||
| - `aps-cli` | ||
|
|
||
| ## Acceptance Criteria | ||
|
|
||
| - Release fetches use one checkout-managed credential, the release distribution contract rejects manual duplicate Authorization headers, and a v1.1.0 workflow dispatch passes provenance. | ||
|
|
||
| ## No-spec Rationale | ||
|
|
||
| This repairs CI authentication plumbing without changing the aps CLI contract or release artifact semantics. |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,12 @@ | ||
| --- | ||
| change: CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be | ||
| artifact: context | ||
| --- | ||
|
|
||
| # Context | ||
|
|
||
| The v1.1.0 tag push failed twice before provenance verification because the | ||
| release workflow constructed a manual HTTP Authorization header. Git reported | ||
| `Failed sending HTTP request` while fetching the tag. The checkout action can | ||
| manage the job-scoped credential itself, avoiding custom header construction | ||
| while retaining least-lived GitHub token authentication. |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,36 @@ | ||
| { | ||
| "schema_version": 1, | ||
| "id": "CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be", | ||
| "slug": "fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be", | ||
| "title": "Fix release workflow fetch authentication so signed tags and attest notes can be fetched on GitHub-hosted runners", | ||
| "description": "Fix release workflow fetch authentication so signed tags and attest notes can be fetched on GitHub-hosted runners", | ||
| "kind": "bug_fix", | ||
| "state": "implementing", | ||
| "base_commit": "7373d124ebb3823c1f7f19651dfffe4d7ed83f51", | ||
| "created_at": 1785303663, | ||
| "updated_at": 1785303960, | ||
| "affected_specs": [ | ||
| "aps-cli" | ||
| ], | ||
| "affected_paths": [ | ||
| ".github/workflows/release.yml", | ||
| "Scripts/test-release-distribution.sh", | ||
| "Scripts/test-release-provenance.sh", | ||
| ".specsync/change-sequence.json" | ||
| ], | ||
| "no_spec_change": true, | ||
| "no_spec_change_rationale": "This repairs CI authentication plumbing without changing the aps CLI contract or release artifact semantics.", | ||
| "acceptance_criteria": [ | ||
| "Release fetches use one checkout-managed credential, the release distribution contract rejects manual duplicate Authorization headers, and a v1.1.0 workflow dispatch passes provenance." | ||
| ], | ||
| "selected_artifacts": [ | ||
| "context", | ||
| "testing", | ||
| "tasks" | ||
| ], | ||
| "dependencies": [], | ||
| "answers": { | ||
| "architecture_risk": "no", | ||
| "public_contract": "no" | ||
| } | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,11 @@ | ||
| --- | ||
| change: CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be | ||
| artifact: tasks | ||
| --- | ||
|
|
||
| # Tasks | ||
|
|
||
| - [x] Replace manual Authorization headers with checkout-managed credentials. | ||
| - [x] Add a regression contract for the release authentication configuration. | ||
| - [x] Run the local verification lane. | ||
| - [ ] Merge the repair and dispatch the existing v1.1.0 tag. |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,12 @@ | ||
| --- | ||
| change: CHG-0064-fix-release-workflow-fetch-authentication-so-signed-tags-and-attest-notes-can-be | ||
| artifact: testing | ||
| --- | ||
|
|
||
| # Testing | ||
|
|
||
| - `Scripts/test-release-distribution.sh` asserts both release checkouts persist | ||
| their job credential and rejects manual Authorization-header construction. | ||
| - `fledge lanes run verify` exercises the release distribution contract. | ||
| - A `workflow_dispatch` run for `v1.1.0` proves tag, default-branch, and attest | ||
| note fetches succeed on the GitHub-hosted runner. |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -32,6 +32,8 @@ grep -Fq 'RELEASE_TAG: ${{ needs.provenance.outputs.tag }}' "$workflow" | |
| grep -Fq 'APS_VERSION="${RELEASE_TAG#v}"' "$workflow" | ||
| grep -Fq 'test "$RELEASE_TAG" = "v$(cat VERSION)"' "$workflow" | ||
| grep -Fq 'test "$("$BIN_DIR/aps" --version)" = "${RELEASE_TAG#v}"' "$workflow" | ||
| test "$(grep -c 'persist-credentials: true' "$workflow")" -eq 2 | ||
| ! grep -Fq 'authorization="$(printf' "$workflow" | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
When the workflow contains the forbidden text, AGENTS.md reference: AGENTS.md:L125-L126 Useful? React with 👍 / 👎. |
||
| grep -Fq 'fetch aps-linux-x86_64-portable.tar.gz' "$formula_workflow" | ||
| grep -Fq 'Scripts/render-homebrew-formula.py' "$formula_workflow" | ||
| grep -Fq 'Homebrew formula updates require a stable SemVer tag' "$formula_workflow" | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Persisting the checkout credential here leaves an
http.https://github.com/.extraheaderAuthorization value in the repository, but the unchanged post-publication step at lines 264-267 adds another value withgit -c; Git treatshttp.extraHeaderas multivalued (git config --get-allexposes both), so that fetch sends duplicate Authorization headers and can fail the Release workflow after assets are uploaded. Because.github/workflows/post-release-formula.ymlonly updates the formula when this workflow concludes successfully, affected releases will not reach Homebrew. Use the persisted credential for that final fetch as well instead of constructing another header.AGENTS.md reference: AGENTS.md:L125-L126
Useful? React with 👍 / 👎.